Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 26 Mar 2004 20:45:54 +0800
From:      "Kang Liu" <liukang@bjpu.edu.cn>
To:        <freebsd-gnats-submit@FreeBSD.org>
Cc:        delphij@frontfree.net
Subject:   ports/64770: [maintainer]SECURITY FIX,update www/phpbb to 2.0.8
Message-ID:  <280304638.26305@bjpu.edu.cn>
Resent-Message-ID: <200403261250.i2QCoUoc045373@freefall.freebsd.org>

next in thread | raw e-mail | index | archive | help

>Number:         64770
>Category:       ports
>Synopsis:       [maintainer]SECURITY FIX,update www/phpbb to 2.0.8
>Confidential:   no
>Severity:       serious
>Priority:       high
>Responsible:    freebsd-ports-bugs
>State:          open
>Quarter:        
>Keywords:       
>Date-Required:
>Class:          maintainer-update
>Submitter-Id:   current-users
>Arrival-Date:   Fri Mar 26 04:50:28 PST 2004
>Closed-Date:
>Last-Modified:
>Originator:     Kang Liu
>Release:        FreeBSD 4.9-STABLE i386
>Organization:
Beijing University of Technology
>Environment:
System: FreeBSD ftp.bjpu.edu.cn 4.9-STABLE FreeBSD 4.9-STABLE #68: Wed Mar 3
11:04:00 CST 2004 root@ftp.bjpu.edu.cn:/usr/obj/usr/src
/sys/FTP i386
>Description:
phpbb 2.0.8 fixed a number of critical security related issues. I hope the
patch could be applied asap.
http://people.freebsd.org/~eik/portaudit/c551ae17-7f00-11d8-868e-000347dd607
f.html for details.
>How-To-Repeat:

>Fix:
--- Makefile.orig	Fri Mar 26 20:13:05 2004
+++ Makefile	Fri Mar 26 20:13:59 2004
@@ -6,8 +6,7 @@
 #
 
 PORTNAME=	phpbb
-PORTVERSION=	2.0.7
-PORTREVISION=	1
+PORTVERSION=	2.0.8
 CATEGORIES=	www
 MASTER_SITES=	${MASTER_SITE_SOURCEFORGE}
 MASTER_SITE_SUBDIR=	${PORTNAME}
@@ -17,8 +16,6 @@
 COMMENT=	A PHP-based bulletin board / discussion forum system
 
 RUN_DEPENDS=
${LOCALBASE}/share/pear/System.php:${PORTSDIR}/devel/pear-PEAR
-
-FORBIDDEN=
http://people.freebsd.org/~eik/portaudit/c551ae17-7f00-11d8-868e-000347dd607
f.html
 
 USE_BZIP2=	yes
 

Index: distinfo
===================================================================
RCS file: /home/ncvs/ports/www/phpbb/distinfo,v
retrieving revision 1.11
diff -u -r1.11 distinfo
--- distinfo	25 Mar 2004 18:03:13 -0000	1.11
+++ distinfo	26 Mar 2004 11:28:47 -0000
@@ -1,2 +1,2 @@
-MD5 (phpBB-2.0.7.tar.bz2) = 252f84cd6de339494f99be59567e9806
-SIZE (phpBB-2.0.7.tar.bz2) = 453926
+MD5 (phpBB-2.0.8.tar.bz2) = 20d9e163e3f3b575639c2a1fbd9e8690
+SIZE (phpBB-2.0.8.tar.bz2) = 456585
Index: pkg-plist
===================================================================
RCS file: /home/ncvs/ports/www/phpbb/pkg-plist,v
retrieving revision 1.9
diff -u -r1.9 pkg-plist
--- pkg-plist	15 Mar 2004 02:26:23 -0000	1.9
+++ pkg-plist	26 Mar 2004 11:28:49 -0000
@@ -11,9 +11,9 @@
 share/phpbb/contrib/fixfiles.sh
 share/phpbb/contrib/template_db_cache.php
 share/phpbb/contrib/template_file_cache.php
-share/phpbb/contrib/visual_confirmation.tar.bz2
+share/phpbb/contrib/visual_confirmation.zip
 share/phpbb/install.php
-share/phpbb/update_to_207.php
+share/phpbb/update_to_208.php
 share/phpbb/upgrade.php
 %%PHPBBDIR%%/admin/admin_board.php
 %%PHPBBDIR%%/admin/admin_db_utilities.php
@@ -76,7 +76,6 @@
 %%PHPBBDIR%%/images/smiles/icon_twisted.gif
 %%PHPBBDIR%%/images/smiles/icon_wink.gif
 %%PHPBBDIR%%/images/spacer.gif
-@exec mkdir -p %B/avatars/upload
 %%PHPBBDIR%%/includes/auth.php
 %%PHPBBDIR%%/includes/bbcode.php
 %%PHPBBDIR%%/includes/constants.php
@@ -114,7 +113,7 @@
 %%PHPBBDIR%%/install/schemas/mysql_schema.sql
 %%PHPBBDIR%%/install/schemas/postgres_basic.sql
 %%PHPBBDIR%%/install/schemas/postgres_schema.sql
-%%PHPBBDIR%%/install/update_to_207.php
+%%PHPBBDIR%%/install/update_to_208.php
 %%PHPBBDIR%%/install/upgrade.php
 %%PHPBBDIR%%/language/index.htm
 %%PHPBBDIR%%/language/lang_english/email/admin_activate.tpl

>Release-Note:
>Audit-Trail:
>Unformatted:



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?280304638.26305>